Currently, Reversible Adversarial Example (RAE) techniques primarily focus on methods based on Reversible Data Hiding (RDH), which typically rely on auxiliary information for adversarial sample recovery, posing risks of image loss due to information transmission. Inspired by recent advancements in diffusion models, we identify two key characteristics of diffusion models: the generation of content is governed by the Gaussian distribution of the diffusion process, and well-trained diffusion models possess robust image restoration capabilities. In selecting the diffusion model, we opt for DDPM to explore the controllability and effectiveness of RAE generation based on diffusion models. Consequently, we propose a novel framework for RAE generation based on diffusion models, termed RAEDiff that achieves self-generation and self-recovery of RAE for the first time. These benefits are attained without the need for additional auxiliary information, thereby enhancing the controllability and effectiveness of RAE in practical applications. To the best of our knowledge, this marks the first introduction of diffusion models into the field of RAE. Comprehensive experiments are conducted to demonstrate the outstanding performance of RAEDiff in terms of adversarial capability, restoration capability, and robustness.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

RAEDiff: Diffusion Models Enable Self-Generation and Self-Recovery of Reversible Adversarial Examples

  • Fan Xing,
  • Xiaoyi Zhou,
  • Hongli Peng,
  • Zhuo Tian,
  • Xuefeng Fan,
  • Yan Zhao

摘要

Currently, Reversible Adversarial Example (RAE) techniques primarily focus on methods based on Reversible Data Hiding (RDH), which typically rely on auxiliary information for adversarial sample recovery, posing risks of image loss due to information transmission. Inspired by recent advancements in diffusion models, we identify two key characteristics of diffusion models: the generation of content is governed by the Gaussian distribution of the diffusion process, and well-trained diffusion models possess robust image restoration capabilities. In selecting the diffusion model, we opt for DDPM to explore the controllability and effectiveness of RAE generation based on diffusion models. Consequently, we propose a novel framework for RAE generation based on diffusion models, termed RAEDiff that achieves self-generation and self-recovery of RAE for the first time. These benefits are attained without the need for additional auxiliary information, thereby enhancing the controllability and effectiveness of RAE in practical applications. To the best of our knowledge, this marks the first introduction of diffusion models into the field of RAE. Comprehensive experiments are conducted to demonstrate the outstanding performance of RAEDiff in terms of adversarial capability, restoration capability, and robustness.